ZeroHour

CVE-2020-14993

PoC
CVSS 3.1
9.8 critical
EPSS
5%p92
Published
()
Modified
Description

A stack-based buffer overflow on DrayTek Vigor2960, Vigor3900, and Vigor300B devices before 1.5.1.1 allows remote attackers to execute arbitrary code via the formuserphonenumber parameter in an authusersms action to mainfunction.cgi.

Vendors
draytek
Products
vigor300b firmware, vigor2960 firmware, vigor3900 firmware
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.